Data Retention
How long each category of data is kept, and the job that deletes it.
These policies are published in English. The English text is the authoritative version; translations are provided for convenience only.
Last updated: 2026-08-01
The registered company details for this service have not been published yet. They will appear here and in the footer as soon as they are confirmed.
Automatically deleted
A background job runs every six hours and deletes the following. These are the windows that are compiled into the running service, not targets.
| Data | Kept for | Measured from |
|---|---|---|
| Search execution logs | 180 days | Creation |
| Authentication tokens (password reset, email verification) | 30 days | Expiry, or consumption if earlier used |
| Directory admission decisions | 365 days | Creation |
| HS-code, top-buyer and buyer-preview caches | Until their own expiry timestamp; a job sweeps hourly | Per-row TTL |
| Application log files | About 31 daily files | Rolling file limit |
Kept until you delete it
The following is retained for as long as the account or listing exists, because deleting it would remove something you are still using. It is deleted on request, or when an account is closed.
- Your account record (name, email, password hash, plan, Google identifier).
- Your searches and their stored results.
- Payment records and NOWPayments callback payloads — these are also subject to statutory accounting retention, which overrides a deletion request for the amount and date of a transaction.
- Contact-form and listing-request submissions, including the IP address and user-agent captured with them.
- Documents uploaded to claim or verify a company.
- Website-scrape requests and their extracted suggestions.
- Company profiles in the directory, including profiles built from public sources.
To have any of it removed, write to privacy@shelftap.com, or, for a company listing, use the Remove or correct a company listing form.
Deletion mechanics
Deletion is a hard delete from the operational database, not a soft flag. Because there is no published backup-restore commitment (see Security Overview), we also make no claim about deletion propagating to historical infrastructure snapshots held by the hosting provider.
Known limitation
The purge job deletes at most 2,000 rows per data type per run. If a category ever accumulates faster than roughly 8,000 rows per day, the oldest rows can persist past the stated window until the backlog clears. We publish this rather than describe the windows as absolute.